CVE-2025-3619: Heap buffer overflow in Codecs
Chromium: CVE-2025-3619 Heap buffer overflow in Codecs
Other sources
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3619?
The severity of CVE-2025-3619 is classified as Critical.
How do I fix CVE-2025-3619?
To fix CVE-2025-3619, update Google Chrome to version 135.0.7049.95 or later.
What type of attack does CVE-2025-3619 enable?
CVE-2025-3619 enables a remote attacker to exploit heap corruption via a crafted HTML page.
On which platform does CVE-2025-3619 affect Google Chrome?
CVE-2025-3619 affects Google Chrome on Windows systems.
What can be the potential impact of CVE-2025-3619?
The potential impact of CVE-2025-3619 includes exploitation leading to arbitrary code execution.